Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Engineer, Application Security

Mercor Inc

About Mercor Mercor is defining the future of work. We partner with leading AI labs and enterprises to provide the human intelligence essential to A I development. Our vast talent network trains frontier AI models in the same way teachers teach students: by sharing knowledge, experience, and context that can't be captured in code alone. Today, more than 30,000 experts in our network collectively earn over $2 million a day. Mercor is creating a new category of work where expertise powers AI advancement. Achieving this requires an ambitious, fast‑paced and deeply committed team. You’ll work alongside researchers, operators, and AI companies at the forefront of shaping the systems that are redefining society. Mercor is a profitable Series C company valued at $10 billion. We work in‑person five days a week in our San Francisco, NYC, or London offices. You’ll own application security at a company where the app layer is the highest‑priority security surface. This is not a scan‑and‑triage role. You’ll embed in the development lifecycle, review code for exploitable flaws, build security tooling into CI/CD, and drive vulnerability remediation across a platform serving 300K+ experts and enterprise clients processing sensitive AI training data. We use AI heavily in our own security work. You should be comfortable building alongside AI code‑gen tools, using LLMs to accelerate code review and threat modeling, and automating away the repetitive work that slows AppSec programs down. If you'd rather write a CodeQL query than file a Jira ticket, you’ll fit in here. We're in‑person five days a week at our SF headquarters, with first Fridays remote. What You’ll Build: Security review workflows embedded in the SDLC – PR‑level analysis that catches auth bugs, injection flaws, and business logic errors before they ship SAST/DAST pipelines integrated into CI/CD – shifting security left without slowing down deploys Vulnerability management processes that prioritize by real exploitability, not CVSS score Secure coding standards and guardrails that make the safe path the easy path for 50+ engineers Threat models for new features and architecture changes – especially around AI data pipelines, payment flows, and multi‑tenant boundaries Bug bounty program operations – triaging HackerOne reports, validating findings, and driving fixes to closure What We’re Looking For You've found and fixed real vulnerabilities in production applications – not just run scanners Deep understanding of web application security: OWASP Top 10 is baseline, you think in terms of attack chains and business logic flaws Strong in at least one of Python, TypeScript, or Go – you can read a PR and spot the auth bypass Experience building or tuning SAST/DAST tooling (Semgrep, CodeQL, Snyk, Burp, or similar) You understand modern web frameworks, APIs, and authentication patterns well enough to threat model them Experience managing a vulnerability pipeline – from discovery through prioritization to verified remediation 5+ years of professional experience in application security, security engineering, or software engineering with a strong security focus Bonus Points Experience running or triaging a bug bounty program (HackerOne, Bugcrowd) Offensive security skills – you've done penetration testing and can think like an attacker Experience securing AI/ML applications – model serving APIs, training data pipelines, prompt injection defense Familiarity with supply chain security – dependency scanning, registry firewalls (Socket, Snyk) You've built custom security tooling that a team still uses Contributions to open source security projects or published vulnerability research Why Mercor The problem is real. Application security at scale is hard – you'll build defenses that matter across a fast‑moving platform. AI‑native AppSec – you'll use frontier AI tools daily – for code review, vulnerability analysis, and anything that benefits from an AI co‑pilot. Ownership from day one. You'll own the entire application security domain – from code review processes to CI/CD security to bug bounty operations. See the future early. Working alongside AI labs means you'll understand frontier model capabilities months before the market. #J-18808-Ljbffr Mercor Inc

Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the Security Engineer, Application Security in San Francisco, CA vacancy
  • $325k - $405k

     ...About the Team Security is at the foundation of OpenAI's mission to ensure that artificial general intelligence benefits all...  ...robust security culture. About the Role As a Security Engineer, Application Security you will be responsible for identifying and... 
    Application
    Work at office
    Remote work
    Relocation package

    OpenAI

    San Francisco, CA
    3 days ago
  • $135.48k - $204.93k

    Sr. Security Engineer I - Enterprise Security Remote - Austin Who we are Samsara (NYSE: IOT) is the pioneer of the Connected Operations...  ...of vulnerabilities and misconfigurations in systems and applications. Mentor engineers in the Security team to grow their domain... 
    Application
    Remote work
    Relocation package
    Flexible hours

    Samsara

    San Francisco, CA
    5 days ago
  • $148.5k - $260.1k

    Senior & Lead Security Engineer - Secure AI Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition...  ...If you need a reasonable accommodation during the application or the recruiting process, please submit a request via this... 
    Application

    Centaur Labs

    San Francisco, CA
    2 days ago
  •  ...horizontal AI automation layer used across IT, HR, Finance, Security, Legal, and Engineering. Our mission is to eliminate repetitive, manual work...  ...Catalyst, Elad Gil, and others. Role Overview As Application Security Lead, you'll build and scale the foundations of... 
    Application
    Full time

    Serval

    San Francisco, CA
    3 days ago
  • $189k - $274k

     ...efficient and accessible for all. We're searching for a Staff Security Engineer, Enterprise Security Operations to join our Enterprise...  ...protected by federal or state law. Aurora considers qualified applicants with criminal histories, consistent with applicable federal... 
    Application
    Full time
    Work at office
    Local area
    3 days per week

    Aurora Innovation

    San Francisco, CA
    1 day ago
  •  ...horizontal AI automation layer used across IT, HR, Finance, Security, Legal, and Engineering. Our mission is to eliminate repetitive, manual work...  ...of access. Implement binary authorization and application controls on endpoints, allowlisting and execution policy... 
    Application
    Full time

    Serval

    San Francisco, CA
    2 days ago
  • B Capital is seeking a Security Software Engineer to establish our Application Security function while contributing to various projects within the Security Engineering organization. This role is perfect for individuals who thrive in environments that demand ownership and... 
    Application

    B Capital

    San Francisco, CA
    1 day ago
  • $127k - $249k

    We are hiring an experienced Security Software Engineer (Staff or Senior) for our Infrastructure Security team to design and build scalable security...  ...startups—relying on MongoDB for their most important applications, we’re powering the next era of software. Our compass at... 
    Application
    Work at office
    Local area
    Remote work
    Worldwide
    Flexible hours

    INSIDER

    San Francisco, CA
    1 day ago
  • Aimling is looking for a highly skilled Offensive Security Engineer to join our security team in San Francisco. This role involves planning...  ..., as well as penetration tests across our infrastructure, applications, and AI systems. The ideal candidate has over 5 years of... 
    Application

    Aimling

    San Francisco, CA
    4 days ago
  • $123.7k - $254.67k

     ...here. This role is part of Pinterest’s Corporate Security team and will collaborate closely with engineers to tackle complex enterprise security challenges....  ...remediation of threats across infrastructure and applications. Use AI to accelerate analysis and iteration,... 
    Application
    Work at office
    Local area
    Remote work
    Relocation
    Relocation package

    Pinterest

    San Francisco, CA
    3 days ago
  • $189k - $274k

     ...efficient and accessible for all. We're searching for a Staff Security Engineer to join our Enterprise Security Engineering team, reporting...  ..., identities, and internal infrastructure (not product or application security). * Proficiency in at least one programming... 
    Application
    Full time
    Work at office
    Local area
    3 days per week
    Early shift

    Aurora Innovation

    San Francisco, CA
    1 day ago
  • $189k - $303k

     ...efficient and accessible for all. We’re searching for a Staff Security Engineer, Enterprise Security Architecture. This position is open to...  ...by federal or state law. Aurora considers qualified applicants with criminal histories, consistent with applicable federal,... 
    Application
    Full time
    Work at office
    Local area
    3 days per week

    Aurora Innovation

    San Francisco, CA
    2 days ago
  • $230k - $255k

     ...Full time Location Type Hybrid Department Security About Us: Notion helps you build...  ...path forward to the future. The Notion application is flexible, powerful and always evolving...  ...customers. Notion is looking for security engineers that have a passion for making it as... 
    Application
    Full time
    Work at office
    Local area
    Remote work
    Flexible hours

    Monograph

    San Francisco, CA
    2 days ago
  • Retool Inc. in San Francisco is seeking an Application Security Engineer to enhance our security posture by identifying and addressing systemic security gaps in our codebase. This role is crucial as you will work closely with engineering teams to ensure secure practices... 
    Application

    Retool

    San Francisco, CA
    4 days ago
  • $190k - $280k

     ...software monitoring tools. About The Role The security team is responsible for and committed to securing...  ...goal. Sentry is looking for a Senior Security Engineer to join our growing security team, working across application and platform security domains to drive security... 
    Application
    Work at office

    Sentry

    San Francisco, CA
    3 days ago
  • Braintrust, based in San Francisco, is seeking an Application Security Engineer to ensure security in their high-availability data platform. This role involves reviewing code, leading security initiatives related to AI models, and managing vulnerabilities. The ideal candidate... 
    Application
    Flexible hours

    Braintrust

    San Francisco, CA
    4 days ago
  • $160k - $185k

     ...technology teams to design and implement secure software and practices. You’ll also...  ...controls. About the team The security engineering team is building tooling and processes...  ...in pipeline Perform security reviews of application code Take part in team on call rotation... 
    Application
    Local area
    Immediate start
    Work from home

    Israelvcforum

    San Francisco, CA
    3 days ago
  • $222k - $278k

    A code security company is looking for a Senior Security Engineer to enhance product security. This role involves collaborating with engineering teams to ensure secure application development and infrastructure management. Ideal candidates will have 7+ years of experience... 
    Application
    Work at office

    Semgrep

    San Francisco, CA
    3 days ago
  • Brain Co. in San Francisco is looking for a Security Engineer for Applications & AI. You will be responsible for integrating security practices into product development throughout customer-sensitive environments. Responsibilities include running security tooling, conducting... 
    Application

    Brain Co.

    San Francisco, CA
    4 days ago
  • $123.7k - $254.67k

     ...here [ This role is part of Pinterest’s Corporate Security team and will collaborate closely with engineers to tackle complex enterprise security challenges....  ...of threats across infrastructure and applications. * Use AI to accelerate analysis and iteration,... 
    Application
    Full time
    Work at office
    Local area
    Remote work
    Relocation
    Relocation package

    Pinterest

    San Francisco, CA
    3 days ago
  • Giga AI, based in San Francisco, is seeking a skilled security engineer to build systems ensuring the security of customer data and the platform...  ...the engineering team. Your responsibilities will include application security, developing role-based access controls, and... 
    Application

    Giga AI

    San Francisco, CA
    5 days ago
  • $230k - $275k

     ...customers as fast as possible. Zipline’s security problems aren’t “website got pwned”...  ...wears many hats, and collaborates across engineering disciplines. You’ll join a small, high-...  ...AI) and the OWASP Top 10 for LLM Applications, which explicitly calls out risks like... 
    Application
    Internship
    Work at office
    Local area

    Namely

    South San Francisco, CA
    4 days ago
  • Menlo Ventures is looking for a Sales Engineer to join their team. In this role, you will help developers secure their applications by integrating Semgrep’s products into their workflows. You will demonstrate technical expertise and work closely with customers to enhance... 
    Application

    Menlo Ventures

    San Francisco, CA
    5 days ago
  • $210k - $230k

     ...process. About the Role: We're looking for a Senior Staff Security Engineer to lead Gusto's edge and network security strategy, owning...  ...gender identity or expression, sexual orientation, or other applicable legally protected characteristic. Gusto considers qualified... 
    Application
    Full time
    Work at office
    Local area
    Remote work
    2 days per week
    3 days per week

    gusto

    San Francisco, CA
    a month ago
  • $200k - $300k

     ...the team The Airwallex Information Security Team is a high calibre and highly proactive...  ...app security, Corporate IT and broader engineering functions. What you’ll do As a...  ...the development of security tools and applications to improve Airwallex's security, from inception... 
    Application
    Temporary work
    Local area
    Worldwide

    Airwallex

    San Francisco, CA
    more than 2 months ago
  • $222k - $278k

     ...About Semgrep Semgrep, the leader in code security for builders, empowers invention...  ...Capital, Semgrep is recognized by Gartner in Application Security Testing and is trusted by...  ...mission; and partners closely with the Engineering, People Ops and Go‑to‑Market teams. About... 
    Application
    Currently hiring
    Local area
    Remote work
    Weekend work
    3 days per week

    Semgrep

    San Francisco, CA
    4 days ago
  • $174k - $253k

    Google Inc. is seeking a Security Engineer in San Bruno, California to create a secure environment for users. Responsibilities include analyzing vulnerabilities, leading incident responses, and collaborating with software engineers to safeguard sensitive data. Candidates... 
    Application

    Google Inc.

    San Bruno, CA
    4 days ago
  •  ...Factory is seeking a talented Security Engineer to join our team. In this role, you will play a critical role in developing and maintaining...  ...measures for the protection of our cloud infrastructure, applications, and data, focusing on both preventative controls and rapid... 
    Application
    Work at office

    Factory

    San Francisco, CA
    3 days ago
  • $180k - $225k

     ...ubiquitous. We build the foundation for agent engineering in the real world, helping developers...  ...About the role You’ll be the hands‑on security lead embedded with core product teams...  ...in cloud/infrastructure security or application security (both is a plus!) Own product... 
    Application
    Immediate start
    Flexible hours

    LangChain

    San Francisco, CA
    5 days ago
  •  ...within a Vulnerability Management Program that understands Application Security with 5-7 years of security experience. Experience with any...  ...Secure code review experience using automated toolsets Software Engineering career experience Following Certifications: CISSP, CEH,... 
    Application

    Bridge Technologies and Solutions

    San Francisco, CA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Engineer, Application Security. Be the first to apply!